Browser Screenshots < 1.7.6 - Stored Cross-Site Scripting
mediumThe Browser Screenshots WordPress plugin before 1.7.6 allowed authenticated users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks as the image_class parameter of the browser-shot shortcode was not escaped.
- CVSS:
- 5.4
- Affected:
- up to 1.7.6
- Fixed in:
- 1.7.6
- Disclosed:
- Jun 21, 2021